Claims 




What is claimed is: 



us 



in 



(b) 
(c) 

(d) 



1 2. 
2 



1 5. 
2 

1 6. 
2 



A method f )r on-access computer virus scanning of files in an efficient 
manner, comprising the steps of: 
identifying i process for accessing files and selecting virus detection actions 
based at least in part on the identified process if no identifier is assigned 
thereto; 

assigning aA identifier to the process if no identifier is assigned thereto; 
selecting vims detection actions based at least in part on the identifier if 



existent; anp 
performing 



the virus detection actions on the files. 



The method as recited in claim 1 , wherein the identifier is cleared upon the 



occurrence 



)f a predetermined event. 



1 3. The method 

2 cleared. 

1 4. The method 

2 application 



The method 
application. 



The methoc 
executing 



as recited in claim 2, wherein the identifier is reused after being 



as recited in claim 2, wherein the event is the termination of an 



as recited in claini 4, wherein the identifier is assigned by the 



tHe 



as recited in claim 4, wherein the application is adapted for 
process. 
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1 

2 
3 
4 
5 
6 
7 

8 (c) 
9 

10 (d) 



(a) 



(b) 



A computer program product for on-access computer virus scanning of files 
in an efficient manner, comprising: 

computer code f :>r identifying a process for accessing files and selecting virus 
detection action;; based at least in part on the identified process if no 
identifier is assi^ed thereto; 

computer code for assigning an identifier to the process if no identifier is 
assigned thereto; 

computer code fcr selecting virus detection actions based at least in part on 
the identifier if existent; and 

computer code foi performing the virus detection actions on the files. 



in 
.n 

5 



1 8. The computer program product as recited in claim 7, wherein the identifier is 

2 cleared upon the occurrence of a predetermined event. 

1 9. The computer prog am product as' recited in claim 8, wherein the identifier is 

2 reused after being c eared. 

1 10. The computer program product as recited in claim 8, wherein the event is the 

2 termination of an aj plication. 

1 11. The computer program product as recited in claim 10, wherein the identifier 

2 is assigned by the application. 

1 12. The computer progr im product as recited in claim 1 0, wherein the 

2 application is adapted for executing the process. 



1 13. A system for on-accqss computer virus scanning of files in an efficient 

2 manner, comprising: | 

3 (a) logic for identifying a process for accessing files and selecting virus detection 

4 actions based at least \n part on the identified process if no identifier is 

5 assigned thereto; 
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(b) logic for assijpiing an identifier to the process if no identifier is assigned 
thereto; 

(c) logic for selecting virus detection actions based at least in part on the 
identifier if existent; and 

(d) logic for performing the virus detection actions on the files. 



14. The system as 
occurrence of 

15. The system as 
cleared. 

16. The system as 
application. 

17. The system as 
application. 



recited in claim 13, wherein the identifier is cleared upon the 
predetermined event. 

recited in claim 14, wherein the identifier is reused after being 

recited in claim 14, wherein the event is the termination of an 

/ 

ecited in claim 16, wherein the identifier is assigned by the 



18. The system as recited in claim 16,] wherein the application is adapted for 
executing the process. 
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